NatJack Attacks, Persistent Entra ID Malware, Two Linux Flaws, AI-Found HTTP Desync Attacks

THN Daily Updates
Newsletter
cover

Blockchain, Crypto and DeFi: Bridging Finance and Technology ($45.00 Value) FREE for a Limited Time

Unlock the future of finance with Blockchain, Crypto, and DeFi

Download Now Sponsored
LATEST NEWS Aug 7, 2026

Growing Up The Hard Way

Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand t...

Read More
Twitter Facebook LinkedIn

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2...

Read More
Twitter Facebook LinkedIn

AI Moves Fast. Security Hasn't Caught Up

Traditional controls are no longer enough for autonomous AI agents. Glean’s AWARE Framework provides a security model for evaluating agent intent, context, guardrails, runtime risk, and ecosystem observability.

Read More
Twitter Facebook LinkedIn

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose ...

Read More
Twitter Facebook LinkedIn

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync v...

Read More
Twitter Facebook LinkedIn

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The atta...

Read More
Twitter Facebook LinkedIn

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next...

Read More
Twitter Facebook LinkedIn

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtu...

Read More
Twitter Facebook LinkedIn
cover

Blockchain, Crypto and DeFi: Bridging Finance and Technology ($45.00 Value) FREE for a Limited Time

Unlock the future of finance with Blockchain, Crypto, and DeFi

Download Now Sponsored

This email was sent to sikubaycom.s3cr3tz@blogger.com. You are receiving this newsletter because you opted-in to receive relevant communications from THN. To manage your email newsletter preferences, please click here.

Contact THN: info@thehackernews.com
Unsubscribe

THN | K.P BLock, Pitampura, Delhi